Maxthon develops a lightweight web browser and cloud-based browsing platform, with a narrowly focused vulnerability footprint centered on its browser product and related services. The recurring exposure reflects typical browser-implementation challenges: cross-site scripting, buffer boundary violations, improper access control, and input-neutralization weaknesses that arise in rendering and script-execution contexts, though public exploit code has been developed for vulnerabilities affecting this vendor. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maxthon over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3667MEDIUM Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header. | Aug 13, 2008 | 6.8 | 29 | NO | YES |
CVE-2019-16647HIGH Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows. | Oct 29, 2019 | 7.2 | 25 | NO | NO |
CVE-2010-5246MEDIUM Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan horse (1) RSRC32.dll or (2) dwmapi.dll file | Sep 7, 2012 | 6.9 | 20 | NO | NO |
CVE-2014-1449MEDIUM The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API. | Dec 25, 2014 | 5.0 | 19 | NO | NO |
CVE-2005-1091HIGH Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page. | May 2, 2005 | 7.5 | 19 | NO | NO |
Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property. | May 2, 2005 | 2.6 | 18 | NO | YES |
CVE-2005-1090MEDIUM Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files. | May 2, 2005 | 6.4 | 18 | NO | NO |
CVE-2009-3018MEDIUM Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cro | Aug 31, 2009 | 4.3 | 16 | NO | NO |
CVE-2009-3006MEDIUM Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the vict | Aug 28, 2009 | 4.3 | 15 | NO | NO |
CVE-2006-6985MEDIUM Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that refere | Feb 9, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maxthon.
Media articles that mention a CVE ID that affects a product developed by Maxthon — matched by CVE ID, not by vendor name.